Closed Bug 1937080 Opened 11 months ago Closed 10 months ago

Mitigate breakage risks for parent-process script security

Categories

(Core :: DOM: Security, enhancement)

enhancement

Tracking

()

RESOLVED FIXED
136 Branch
Tracking Status
firefox136 --- fixed

People

(Reporter: freddy, Assigned: tschuster)

References

(Blocks 1 open bug)

Details

(Whiteboard: [domsecurity-active])

Attachments

(4 files)

We should build logging to get insights into what kind of event handlers are added in the real world (document, element, position, event handler attribute, script source, JavaScript stack trace...).

We should be able to disable the enforcement mechanism at runtime (pref? remote settings?)

Whiteboard: [domsecurity-active]
See Also: → 1939490
Attachment #9445333 - Attachment description: WIP: Bug 1937080 - Drive by cleanup: Don't pass the sample string to the GatherSecurityPolicyViolationEventData function → Bug 1937080 - Drive by cleanup: Don't pass the sample string to the GatherSecurityPolicyViolationEventData function. r?freddyb
Attachment #9445334 - Attachment description: WIP: Bug 1937080 - Don't strip CSP report URIs when the mSelfURI is chrome: → Bug 1937080 - Don't strip CSP report URIs when the mSelfURI is a chrome: URL. r?freddyb
Attachment #9444714 - Attachment description: WIP: Bug 1937080 - Make the <meta> CSP in browser.xhtml pref controllable. → Bug 1937080 - Make the <meta> CSP in browser.xhtml pref controllable. r?freddyb
Attachment #9445335 - Attachment description: WIP: Bug 1937080 - Block inline event handlers in Nightly and collect telemetry → Bug 1937080 - Block inline event handlers in Nightly and collect telemetry. r?freddyb!,Gijs!
Pushed by tschuster@mozilla.com: https://hg.mozilla.org/integration/autoland/rev/3fade7db9688 Drive by cleanup: Don't pass the sample string to the GatherSecurityPolicyViolationEventData function. r=freddyb https://hg.mozilla.org/integration/autoland/rev/c33b6add9eab Don't strip CSP report URIs when the mSelfURI is a chrome: URL. r=freddyb https://hg.mozilla.org/integration/autoland/rev/b835e8ac47e3 Make the <meta> CSP in browser.xhtml pref controllable. r=freddyb https://hg.mozilla.org/integration/autoland/rev/a20a4eb224da Block inline event handlers in Nightly and collect telemetry. r=freddyb,Gijs,saschanaz
Regressions: 1940393
Blocks: 1940941
Blocks: 1941322
Blocks: 1942991
See Also: → 1942622
Blocks: 1950047
Blocks: 1953374
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: